Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dia | Jul 30, 2024 | Mar 30, 2006 |
| Freebsd | — | Upgrade diaUpgrade dia-gnome | Dec 10, 2025 | Apr 5, 2006 |
| Gentoo Linux | — | Upgrade app-office/dia. | Oct 30, 2017 | Mar 30, 2006 |
| Ubuntu | — | Upgrade dia-gnome | Nov 8, 2024 | Mar 30, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub